Home | Contact Us


Posts Tagged ‘privacy’

Lower Merion School District Laptop Scandal

Sunday, February 21st, 2010

A law suit has been filed against the Lower Merion School District accusing them of spying on students through laptop webcams.

In response, the school has issued a statement:

Yesterday I reported to you on the early phases of the school district’s response to questions raised about the security-tracking software feature that was installed on student laptop computers. While we were able to address many of your initial questions and concerns, I regret we were not immediately in a position to answer all of your questions. Our goal is to be as open as possible, while preserving student privacy, and ensure that over time we have answered to your satisfaction every question about this situation and the broader issue of technology and privacy.

We are a school district that embraces the use of leading-edge technology in our instructional program, encourages all forms of free expression, and must do everything possible to safeguard individual privacy. For these and other reasons, this matter is of the highest importance. In this regard, we have retained the services of Henry E. Hockeimer, Jr., Esq., a local attorney and former federal prosecutor, to assist in our comprehensive review of relevant policies and past practices, as well as assist us in implementing appropriate improvements.

Despite some reports to the contrary, be assured that the security-tracking software has been completely disabled. As I noted yesterday, this feature was limited to taking a still image of the computer user and an image of the desktop in order to help locate the reported missing, lost, or stolen computer (this includes tracking down a loaner computer that, against regulations, might be taken off campus). While we understand the concerns, in every one of the fewer than 50 instances in which the tracking software was used this school year, its sole purpose was to try to track down and locate a student’s computer. Before answering additional questions below, it is important to clear up the matter of notice to students and parents of the existence of the security software. While certain rules for laptop use were spelled out – such as prohibitive uses on and off school property – there was no explicit notification that the laptop contained the security software. This notice should have been given and we regret that was not done.

Once again, we regret this situation has been a source of concern and disruption, and trust that we will soon have stronger privacy policies in place as a result of the lessons learned and our comprehensive review that is now underway. If you have any questions or concerns, please email us at info@lmsd.org. Additional information has been posted on our website, www.lmsd.org.

Thank you for your time and attention.

Sincerely,

Dr. Christopher W. McGinley?
Superintendent of Schools?
Lower Merion School District

Google’s Chrome Web Browser Helps Protect Your Privacy

Friday, January 23rd, 2009

Full Article

Did you think Google.com was just a search engine? Well, they do lots of other things, such as, invented a cell phone, mapping and aerial photos.

Now, they have developed a web browser that helps protect your personal information. Your browsing history, cookies and other Internet activity are treated with special care.

Google’s New Web Browser Let’s You Go Incognito

Sunday, January 18th, 2009

Web browsing has become safer with Chrome, Google.com ’s browser. You can download if for free. It’s lightweight on your computer resources but heavy duty on surfing the web. Pages load faster.

There is also an awesome feature that is the antithesis of Microsoft’s Internet Explorer (IE) web browser — secure browsing. Whereas Microsoft tries to track your movements and uses practices that are questionable for your privacy and security, Google has built in features to help protect you. In particular, you can click on the little wrench icon in the upper right hand corner and select, “New incognito window.”

A new browser window opens and tells you:

You’ve gone incognito. Pages you view in this window won’t appear in your browser history or search history, and they won’t leave other traces, like cookies, on your computer after you close the incognito window. Any files you download or bookmarks you create will be preserved, however.

Going incognito doesn’t affect the behavior of other people, servers, or software. Be wary of:
* Websites that collect or share information about you
* Internet service providers or employers that track the pages you visit
* Malicious software that tracks your keystrokes in exchange for free smileys
* Surveillance by secret agents
* People standing behind you

New in-session phishing attack could fool experienced users

Wednesday, January 14th, 2009

By Joel Hruska | Published: January 13, 2009 – 11:15AM CT

Another year, another form of phishing. This one, I have to admit, is pretty good in terms of potentially fooling a user. Unlike most phishing attack vectors, it doesn’t rely on the victim being ignorant and/or moronic. The new technique has been dubbed “in-session” phishing and it stays out of your e-mail altogether.

Related StoriesStudy: PEBKAC still a serious problem when it comes to PC security
Twishing attacks steal data in 140 characters or less
Report: Many evils lurk in the “dark corners” of the Internet
Google opens up malware blacklist API
Security researchers with Trusteer have published a report (PDF) on this new type of phishing along with a suitably vague description of how the attack works. As its name implies, in-session phishing requires that the victim first log into a secure website; Trusteer uses an online bank site as one example of a tasty target.

Here’s how the attack works: A user legitimately logs into his bank, authenticates, and then does whatever he logged in to do. Once finished, he opens another browser tab (or browser window) and leaves the bank website open. Shortly thereafter, he encounters a website that has been injected with the malicious code in question. Once run, the malware creates a pop-up (supposedly from the bank or secure site that’s still open in another tab or window. The “authentic” pop-up prompts the user to enter his login credentials again in order to resume the session. Trusteer notes that the attack could be used to present different types of lures including online surveys or mini-flash games (punch the Yeti, enter your personal data, and win a free Llama!).

In order for the attack to function, Trusteer states that two conditions must be met. First, a website must be compromised and infected—the higher traffic the better, obviously. Secondly, the downloaded malware must be able to identify whether or not the unknowing carrier is logged into a relevant website. Trusteer does not state how long the window of opportunity is open for this particular attack to execute, but does note that the malware infection is temporary.

Trusteer explains how the bug works. It is present in the JavaScript engine used by popular browsers like IE, Firefox, and Safari, as well as Chrome, and allows a site to determine whether a user is also logged into another site.

The source of the vulnerability is a specific JavaScript function. When this function is called it leaves a temporary footprint on the computer and any other website can identify this footprint. Websites that use this function in a certain way are traceable. Many websites, including financial institutions, online retailers, social networking websites, gaming, and gambling websites use this function and can be traced.

The researchers recommend that users and companies deploy appropriate web security tools (which the company happens to sell), immediately log out of any secure sites once you’ve finished your tasks (good advice), and to be extremely wary of pop-ups that randomly drop in if you haven’t clicked anything.

The JavaScript vulnerability that Trusteer has discovered obviously needs patching, but in-session phishing doesn’t appear to be a major threat. In order to function successfully, the malware requires that a user have simultaneous browser windows open to both a login/secure site and an infected site, and that the secure site is on the malware’s pregenerated list of targets. There are some rather simple ways for banks and other targeted institutions to fight back; options include rapid disconnects if a user becomes idle and prominent notifications of the company’s login policy.

Many companies (Blizzard and AOL come to mind) prominently and repeatedly inform customers that neither the company nor its representatives will ever, ever, ask a user to disclose their password. A similar warning against in-session phishing might state that the company will never ask users to log in via a pop-up or any third-party service. Between currently available solutions and inevitable patches, I think in-session phishing is going to find its nets mostly empty.